A Splunk server is not just another app when it sits in the monitoring path. If an attacker reaches this flaw, they can do more than run code on one box: they can interfere with security visibility, tamper with logs, and pull stored credentials from the platform that other teams trust to tell them what is happening.
CVE-2026-20253 affects Splunk Enterprise 10.2 before 10.2.4 and 10.0 before 10.0.7, with Splunk Cloud fixes at 10.4.2604.3 and 10.2.2510.14. The bug is in the PostgreSQL sidecar service endpoint, which lacks authentication and lets a network-reachable caller invoke file operations; public PoC followed quickly, Splunk confirmed limited in-the-wild exploitation, and CISA put it in KEV with a June 21 deadline for federal agencies.
That turns patching into a visibility problem as much as a code-execution problem. An attacker who owns Splunk can hide follow-on activity and use what the platform stores to move deeper into the environment.